How to implement Client IP based routing using Istio features?

Viewed 449

I am trying to achieve Client IP based routing using Istio features.

I have two versions of application V1(Stable) and V2(Canary). I want to route the traffic to the canary version(V2) of the application if the Client IP is from a particular CIDR block (Mostly the CIDR my org) and all other traffic should be routed to the stable version(V1) which is the live traffic.

Is there any way to achieve this feature using Istio?

1 Answers

Yes, this is possible.


Since you have a load balancer in front of the kubernetes cluster, first question to address is preserve client IP because due to NAT load balancer opens another session to the internal side to kubernetes cluster and source IP is lost. It has to be preserved. This can be done in different ways depending on load balancer type used. Please see:

Source IP address of the original client


Next part is to configure a virtual service to route the traffic based on client IP. It was solutioned for HTTP traffic. Below is a working example:

apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: app-vservice
  namespace: test
spec:
  hosts:
  - "app-service"
  http:
  - match:
    - headers:
        x-forwarded-for:
          exact: 123.123.123.123
    route:
    - destination:
        host: app-service
        subset: v2
  - route:
    - destination:
        host: app-service
        subset: v1

Source - Github issue comment

There is also a comment about TCP and usage addresses in ServiceEntry.

Related